An update that fixes two vulnerabilities is now available.. openSUSE Security Update: Security update for varnish ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:0808-1 Rating: moderate References: #1169039 #1169040 Cross-References: CVE-2019-20637 CVE-2020-11653 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for varnish fixes the following issues: - CVE-2019-20637: Fixed an information leak when handling one client request and the next on the same connection (boo#1169040) - CVE-2020-11653: Fixed a performance loss due to an assertion failure and daemon restart when communicating with TLS termination proxy that uses PROXY version 2 (boo#1169039) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-808=1 Package List: - openSUSE Leap 15.1 (x86_64): libvarnishapi2-6.2.1-lp151.3.6.1 libvarnishapi2-debuginfo-6.2.1-lp151.3.6.1 varnish-6.2.1-lp151.3.6.1 varnish-debuginfo-6.2.1-lp151.3.6.1 varnish-debugsource-6.2.1-lp151.3.6.1 varnish-devel-6.2.1-lp151.3.6.1 References: https://www.suse.com/security/cve/CVE-2019-20637.html https://www.suse.com/security/cve/CVE-2020-11653.html https://bugzilla.suse.com/1169039 https://bugzilla.suse.com/1169040 -- . The latest varnish update addresses two specific bugs in openSUSE. Solutions have been implemented to tackle data exposure vulnerabilities and enhance overall system efficiency.. openSUSE Security Update, varnish, information leak, performance issue. . LinuxSecurity.com Team
If fetchmail is running in daemon mode, it must be restarted for this update to take effect (use the "fetchmail --quit" command to stop the fetchmail process).. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2009-8780 2009-08-20 20:33:17 --------------------------------------------------------------------------------Name : fetchmail Product : Fedora 11 Version : 6.3.9 Release : 5.fc11 URL : https://www.berlios.de/software/fetchmail/ Summary : A remote mail retrieval and forwarding utility Description : Fetchmail is a remote mail retrieval and forwarding utility intended for use over on-demand TCP/IP links, like SLIP or PPP connections. Fetchmail supports every remote-mail protocol currently in use on the Internet (POP2, POP3, RPOP, APOP, KPOP, all IMAPs, ESMTP ETRN, IPv6, and IPSEC) for retrieval. Then Fetchmail forwards the mail through SMTP so you can read it through your favorite mail client. Install fetchmail if you need to retrieve mail over SLIP or PPP connections. --------------------------------------------------------------------------------Update Information: If fetchmail is running in daemon mode, it must be restarted for this update to take effect (use the "fetchmail --quit" command to stop the fetchmail process). --------------------------------------------------------------------------------ChangeLog: * Wed Aug 19 2009 Vitezslav Crhonek - 6.3.9-5 - Fix SSL null terminator bypass (CVE-2009-2666) * Tue Jun 9 2009 Adam Jackson 6.3.9-4 - Rebuild to get rid of libkrb4 dependency. --------------------------------------------------------------------------------References: [ 1 ] Bug #515804 - CVE-2009-2666 fetchmail: SSL null terminator bypass https://bugzilla.redhat.com/show_bug.cgi?id=515804 --------------------------------------------------------------------------------This update can be installed with the "yum" update program. Use su -c 'yumupdate fetchmail' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.